Weaknesses of type CWE-200

4,922 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2019-3016MEDIUMIn a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in theEPSS 0.6%CVE-2023-22847MEDIUMInformation disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialized View (IMMV) createEPSS 0.6%CVE-2026-9289MEDIUMWordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API EndpointsEPSS 0.6%CVE-2023-27894MEDIUMSensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platformEPSS 0.6%CVE-2025-23173HIGHThe Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By defaEPSS 0.6%CVE-2024-10285CRITICALCE21 Suite <= 2.2.0 - JWT Token DisclosureEPSS 0.6%CVE-2024-13110MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System Exam Answer PaperController.java, information disclosureEPSS 0.6%CVE-2014-125102MEDIUMBestwebsoft Relevant Plugin Thumbnail information disclosureEPSS 0.6%CVE-2021-25649MEDIUMAvaya Utility Services Sensitive Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-2792MEDIUMEphemeral messages return private channel contents in permalink previewsEPSS 0.6%CVE-2023-36507MEDIUMWordPress BookingPress Plugin <= 1.0.64 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-51027CRITICALAn issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.EPSS 0.6%CVE-2022-31046MEDIUMInformation Disclosure via Export Module in TYPO3 CMSEPSS 0.6%CVE-2023-40002MEDIUMWordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2026-31909HIGHApache OFBiz: Unauthenticated Shipment Label Image DisclosureEPSS 0.6%CVE-2023-30993MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2026-70478CRITICALFlowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected serviceEPSS 0.6%CVE-2026-72548HIGHOpenSignLabs OpenSign - Information DisclosureEPSS 0.6%CVE-2024-11265MEDIUMWp Maximum Upload File Size <= 1.1.3 - Authenticated (Author+) Full Path DisclosureEPSS 0.6%CVE-2023-6214HIGHHT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_productsEPSS 0.6%